概要
Bio: Dennis Kengo (Nilsson) Oka works as Global Technical & Cybersecurity Advisor at IAV.…
アクティビティ
-
40 min flew by!!Thanks so much everyone!! #opensource #oss #osssummit #linux #automotive #ospo
40 min flew by!!Thanks so much everyone!! #opensource #oss #osssummit #linux #automotive #ospo
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
Understand how security assurance levels guide protection efforts throughout vehicle development. Learn to determine appropriate security controls…
Understand how security assurance levels guide protection efforts throughout vehicle development. Learn to determine appropriate security controls…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
職務経験
出版物
-
Building Secure Automotive IoT Applications: Developing robust IoT solutions for next-gen automotive software
Packt
Explore modern vehicle architectures designed to support automotive IoT use cases
Discover cybersecurity practices and processes to develop secure automotive IoT applications
Gain insights into how cloud technologies and services power automotive IoT applicationsその他の著者出版物を表示 -
Building Secure Cars: Assuring the Automotive Software Development Lifecycle
Wiley
Explores how the automotive industry can address the increased risks of cyberattacks and incorporate security into the software development lifecycle
-
A security assessment study and trial of Tricore-powered automotive ECU
CODE BLUE 2014
ECU software is responsible for various functionality in the vehicle, e.g., engine control and driver assistance systems. Therefore, bugs or vulnerabilities in such systems may have disastrous impacts affecting human life. We consider possible vulnerabilities in ECU software and examine attack techniques for such vulnerabilities. Since we did not acquire and reverse-engineer actual ECU software, we first consider in theory how and if attacks are possible under the assumption that there would…
ECU software is responsible for various functionality in the vehicle, e.g., engine control and driver assistance systems. Therefore, bugs or vulnerabilities in such systems may have disastrous impacts affecting human life. We consider possible vulnerabilities in ECU software and examine attack techniques for such vulnerabilities. Since we did not acquire and reverse-engineer actual ECU software, we first consider in theory how and if attacks are possible under the assumption that there would exist memory corruption vulnerabilities in ECU software. For our investigation, we consider the ECU microcontroller architecture TriCore1797 which exists in a number of ECUs. In contrast to x86 architecture, the return address is not stored on the stack; therefore, we assumed that performing code execution by stack overflow would not be easy. We investigated if it would be possible to perform arbitrary code execution based on approaches from the PC environment and also if other attack approaches could be considered. We considered the following attack approaches:
1) Overwriting a function pointer stored on the stack by performing a buffer overflow to execute code;
2) Overwriting the memory area handling context switching used by TriCore itself to execute code;
3) Overwriting the vector tables used by interrupt and trap functions.
Moreover, using a TriCore evaluation board and software created to perform the experiments, we tested the various attack approaches. We confirmed that several attack approaches are not possible due to security mechanisms provided by the microcontroller or differences in the microcontroller architecture compared to traditional CPUs. However, under certain specific conditions, as a result of performing a buffer overflow attack to overwrite a function pointer, we manage to make the TriCore jump to an address of our choosing and execute the code already stored on that location.その他の著者出版物を表示 -
Securing the Wireless Vehicle-to-Infrastructure Environment: Diagnostics and Firmware Updates
ISBN-13: 978-3836465922
In recent years, information technology has entered the automobile domain. There is an emerging trend among automobile manufacturers to perform wireless diagnostics and firmware updates. This wireless vehicle-to-infrastructure environment, where the automobile manufacturer establishes a wireless connection to a vehicle, introduces a number of security threats. This book focuses on the security aspects of such environments. Security challenges for this and similar scenarios are first identified…
In recent years, information technology has entered the automobile domain. There is an emerging trend among automobile manufacturers to perform wireless diagnostics and firmware updates. This wireless vehicle-to-infrastructure environment, where the automobile manufacturer establishes a wireless connection to a vehicle, introduces a number of security threats. This book focuses on the security aspects of such environments. Security challenges for this and similar scenarios are first identified and analyzed. Based on such analyses and the challenges identified therein, specific solutions for the wireless vehicle-to-infrastructure environment are suggested. The security issues and solutions presented in this book may serve as a roadmap for future research in this field, and should be especially useful for professionals in Network Security and Vehicle Communication fields, or anyone else who may be interested in future computer security trends for vehicle-to-infrastructure environments.
特許
-
SECURITY TEST SYSTEM, SECURITY TEST METHOD, FUNCTION EVALUATION DEVICE, AND PROGRAM
発行日: US US2019141074A1
言語
-
English
母国語またはバイリンガル
-
Japanese
ビジネス上級
-
Swedish
母国語またはバイリンガル
Dennis Kengoさんによるその他のアクティビティ
-
We decided to keep the competition open all week - nobody has solved all the challenges yet! Give it a try and sharpen your vehicle…
We decided to keep the competition open all week - nobody has solved all the challenges yet! Give it a try and sharpen your vehicle…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
The Automotive SBOM concept was proposed by Watanabe-san at OpenChain Mini Summit Amsterdam!! The detail will be uploaded to OpenChain…
The Automotive SBOM concept was proposed by Watanabe-san at OpenChain Mini Summit Amsterdam!! The detail will be uploaded to OpenChain…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
V2X and the requirements for it are evolving in the US. As an automotive engineering company, we see the potential to lead with our #Lumits SaaS…
V2X and the requirements for it are evolving in the US. As an automotive engineering company, we see the potential to lead with our #Lumits SaaS…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
Just back from #China and more convinced than ever about what great automotive execution requires. First I have not seen technology that IAV cannot…
Just back from #China and more convinced than ever about what great automotive execution requires. First I have not seen technology that IAV cannot…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
Everyone at Block Harbor has deep domain expertise in product cyber - and few people in the world have over 20 years. It is an honor to be able to…
Everyone at Block Harbor has deep domain expertise in product cyber - and few people in the world have over 20 years. It is an honor to be able to…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
We’re all set and ready to go at the ITS World Congress in Atlanta, GA! Come visit us in Hall A, booth 623. #V2X #InCabin #Automotive…
We’re all set and ready to go at the ITS World Congress in Atlanta, GA! Come visit us in Hall A, booth 623. #V2X #InCabin #Automotive…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
I’m looking forward to the Panel with Automotive friends at Amsterdam!! #opensource #oss #ospo #linux #automotive https://lnkd.in/gfHhb-KC
I’m looking forward to the Panel with Automotive friends at Amsterdam!! #opensource #oss #ospo #linux #automotive https://lnkd.in/gfHhb-KC
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
BSides Tokyo will exhibit a community booth at HITCON again this year. As a new initiative, we will hold a scavenger hunt. Participants will have a…
BSides Tokyo will exhibit a community booth at HITCON again this year. As a new initiative, we will hold a scavenger hunt. Participants will have a…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
The Global Vehicle Cybersecurity Competition is happening now. We prepared some exciting challenges and just like last year, players get to have…
The Global Vehicle Cybersecurity Competition is happening now. We prepared some exciting challenges and just like last year, players get to have…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
Late-ish Defcon wrap-up post incoming💥💥💥 Just as it is every year, this year's Defcon was a blast and a journey. I learn so much every year but…
Late-ish Defcon wrap-up post incoming💥💥💥 Just as it is every year, this year's Defcon was a blast and a journey. I learn so much every year but…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
Learn how TARA and IEC 62443 help IoT teams expose risks, set security levels, and apply controls that protect production, data, and worker safety.
Learn how TARA and IEC 62443 help IoT teams expose risks, set security levels, and apply controls that protect production, data, and worker safety.
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました
-
Explore our Vehicle Security Operations Center demo app for Splunk. Learn how this tool helps security teams visualize, detect, and respond to…
Explore our Vehicle Security Operations Center demo app for Splunk. Learn how this tool helps security teams visualize, detect, and respond to…
Dennis Kengo Oka, Ph.D.さんが「いいね!」しました